|
|
|
|
|
by Sir_Cmpwn
2896 days ago
|
|
>If independent third parties had to audit code _before_ it could be released, we'd get a lot less code a lot slower. So? The JavaScript community could stand to slow down a bit. >We do have a trusted third-party publish new packages – NPM. They remove malicious content as quickly as they can. They might publish, but they certainly don't audit. Anyone can publish a package on npm in tens of seconds and it's immediately live for anyone to install. It's not even signed. This looks nothing like a Linux distro. |
|
Why is there this call for all software development to slow down? As if the bad actors will also listen and just slow down trying to attack...